Microsoft: September Windows updates break Always On VPN connections

A critical issue has been discovered in Microsoft’s latest Windows 11 security updates, affecting Always On VPN connections for thousands of users worldwide. The September 2026 patches, designed to bolster system security, have inadvertently caused problems with this popular remote access solution.

Always On VPN is a secure connection technology that allows employees to access their company network from anywhere without the need for manual login or configuration. It’s particularly useful for organizations with complex networks and varying levels of security requirements. The technology uses modern protocols like IKEv2 and SSTP to establish a secure tunnel between devices and the corporate network, while also supporting multi-factor authentication (MFA) to enhance security.

The issue, reported by Microsoft in a service alert shared with IT administrators, occurs when Always On VPN is configured to automatically try another connection method if the initial attempt fails. This can lead to persistent “Connecting” states or repeated connection attempts that never succeed. Users may also encounter an error message stating that the specified port is already in use.

Microsoft has confirmed that this problem affects various Windows 11 versions, including 26H1 (KB5124012), 25H2 (KB5124008), and 24H2 (KB5124008). Although a permanent fix is still being worked on by Microsoft, the company has offered a temporary workaround for affected customers. To resolve the issue, IT administrators can change the Always On VPN profile from automatic protocol selection to a single protocol – either SSTP or IKEv2 only – depending on their environment and configuration requirements.

This isn’t the first problem associated with this month’s cumulative updates. Microsoft has already released emergency patches to address Hyper-V issues, Remote Desktop Services failures, and USB audio problems triggered by these same updates. Furthermore, separate issues have been reported that block some Windows 11 users from logging in with valid domain credentials and may cause the built-in File History backup feature to malfunction.

For IT administrators dealing with Always On VPN connection issues due to these patches, it’s essential to prioritize a thorough assessment of their network configuration and security setup. This includes evaluating protocol selection and configuring single-protocol settings as a temporary fix until Microsoft releases a permanent solution. In the meantime, users should be aware that these updates have caused widespread disruptions and take steps to mitigate potential risks by implementing backup plans and communicating with affected employees.

If you’re an IT administrator struggling to resolve Always On VPN connection issues due to these Windows 11 patches, consider taking the following steps:

* Assess your network configuration and security setup to identify potential vulnerabilities.

* Change the Always On VPN profile from automatic protocol selection to a single protocol – either SSTP or IKEv2 only – as a temporary fix.

* Prioritize communication with affected employees and implement backup plans to minimize disruptions.

By taking proactive measures, you can help ensure continued productivity for your team while Microsoft works on resolving these critical issues.


Source: Bleeping Computer — 2026-09-23